CVE-2025-15620Disclosure(belden / hios_switch)

LOWCVSS 8.6 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

HiOS Switch Platform versions 09.1.00 through 09.4.04 and 10.0.00 through 10.3.00 contain a denial-of-service vulnerability in the web interface that allows remote attackers to reboot the affected device by sending a malicious HTTP GET request to a specific endpoint. Attackers can trigger an uncontrolled reboot condition through crafted HTTP requests to cause service disruption and unavailability of the switch.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hios_switch

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-02); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
hios_switch

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-04-02: 2Mentions · 2026-04-03: 2PoC Mentioned / Linked · 2026-04-02: 1Technical Details · 2026-04-02: 2Technical Details · 2026-04-03: 204-0204-03
Signal classification2 categories
Disclosure
375.0%
PoC
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-022
Disclosure1PoC1
2026-04-032
Disclosure2
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-15620 HiOS Switch Platform versions 09.1.00 prior to 09.4.05 and 10.3.01 contains a denial-of-service vulnerability in the web interface that allows remote attackers to reb… https://www.cve.org/CVERecord?id=CVE-2025-15620

    Post summary

    The post announces CVE‑2025‑15620 as a denial‑of‑service flaw in the HiOS Switch Platform web interface, but does not mention any exploit code, PoC, or remediation.

    00010186
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-15620 - High HiOS Switch Platform versions 09.1.00 prior to 09.4.05 and 10.3.01 contains a denial-of-service vulnerability in the web interface that allows remote attackers to reboot the affected device b... https://www.thehackerwire.com/vulnerability/CVE-2025-15620/ https://t.co/inAYKDlnWa

    Post summary

    The post discloses a new DoS vulnerability (CVE‑2025‑15620) affecting HiOS Switch Platform, detailing affected versions and the nature of the flaw, but does not provide proof‑of‑concept, exploit code, or mitigation information.

    00000183
    160 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-15620: HIGH] Vulnerability in HiOS Switch Platform enables remote attackers to trigger a denial-of-service attack by sending malicious HTTP GET requests, causing service disruption.#cve,CVE-2025-15620,#cybersecurity https://cvefind.com/CVE-2025-15620

    Post summary

    The post announces CVE‑2025‑15620, a high‑severity DoS flaw in the HiOS Switch Platform that can be triggered by crafted HTTP GET requests, but it does not provide any proof‑of‑concept, exploitation code, or remediation details.

    0000075
    617 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2025-15620: HiOS Switch Platform Denial-of-S... Single HTTP GET nukes industrial switches - CWE-306 screams missing auth on critical endpoints, perfect for OT disrupti... https://zerodaysignal.com/vulnerability/CVE-2025-15620 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet highlights a missing‑authentication vulnerability (CVE‑2025‑15620) in HiOS Switch Platform that can be exploited with a single HTTP GET to cause denial of service on industrial switches, referencing a zero‑daysignal article for more detail.

    00000174
    193 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbeldenhios_switch---

Explore more